- Pin all 23 GitHub Actions uses to 40-char commit SHA with tag comments:
actions/checkout@v6 -> d23441a48e516b6c34aea4fa41551a30e30af803 (v6.1.0)
actions/setup-dotnet@v5 -> 26b0ec14cb23fa6904739307f278c14f94c95bf1 (v5.4.0)
actions/upload-artifact@v6 -> b7c566a772e6b6bfb58ed0dc250532a479d7789f (v6.0.0)
actions/download-artifact@v8 -> 3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c (v8.0.1)
softprops/action-gh-release@v2 -> 3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 (v2.6.2)
SHAs verified via gh api repos/<owner>/<action>/git/ref/tags/<tag>
- Move contents:write from workflow level to release steps only
- Add dotnet CycloneDX SBOM generation to linux-release and windows-release
- Add .github/dependabot.yml (github-actions + nuget, weekly, limit 5 PRs)
- Add SECURITY.md with private advisory channel, 72h SLA, threat model
- Add CHANGELOG.md from real git history (Keep a Changelog format)
- Add CONTRIBUTING.md with build/test instructions and Linux test note
- Add CODEOWNERS
- Add .github/ISSUE_TEMPLATE/{bug_report,feature_request}.md
- Add .github/PULL_REQUEST_TEMPLATE.md with mandatory verification checklist
44 lines
711 B
Markdown
44 lines
711 B
Markdown
---
|
|
name: Bug report
|
|
about: Report a defect or unexpected behaviour
|
|
labels: bug
|
|
---
|
|
|
|
## Describe the bug
|
|
|
|
A clear and concise description of what the bug is.
|
|
|
|
## Steps to reproduce
|
|
|
|
1. ...
|
|
2. ...
|
|
3. ...
|
|
|
|
## Expected behaviour
|
|
|
|
What you expected to happen.
|
|
|
|
## Actual behaviour
|
|
|
|
What actually happened.
|
|
|
|
## Environment
|
|
|
|
- **SMM version / commit**: <!-- e.g. v0.1.0-alpha.6 or commit SHA -->
|
|
- **OS and version**: <!-- e.g. Ubuntu 24.04 x64, Debian 12 arm64 -->
|
|
- **Component**: <!-- Control / Agent / Desktop / Bootstrap -->
|
|
|
|
## Logs or error output
|
|
|
|
<details>
|
|
<summary>Relevant log output</summary>
|
|
|
|
```
|
|
paste logs here
|
|
```
|
|
|
|
</details>
|
|
|
|
## Additional context
|
|
|
|
Any other context, screenshots, or related issues.
|